In brief
- A demonstrated consensus flaw let invalid blocks onto Ravencoin starting at height 4,487,776 on Aug. 7.
- Pools 2Miners and RavenMiner, which control a majority of hashpower, are mining a chain that excludes the exploited branch.
- If that chain wins, the network faces a deep reorganization of roughly three days; users and exchanges were told to treat post-flaw transactions as at risk.
The developer behind the Ravencoin cryptocurrency network said Tuesday the blockchain may erase several days of transactions after attackers exploited a flaw in the software that secures the network. As a result, the native token of the network has shed tens of millions in value over the last several hours, crashing 20%.
The project disclosed the bug in a network notice posted to X, warning that deposits, withdrawals, and payments made since Friday are at risk of reversal.
The vulnerability struck on Aug. 7. Ravencoin, which trades as RVN, runs on proof-of-work, the mining model Bitcoin uses and that Ravencoin forked in 2018 to issue tokens. Under that system, the version of the chain backed by the most computing power is the one the network treats as real.
The flaw broke that rule. "The issue caused invalid blocks to be accepted by vulnerable nodes," the notice reads. "The first known invalid block appeared at height 4,487,776 on 2026-08-07 15:44:01 UTC."
Hash power is the total computing muscle miners devote to securing the chain; whoever controls the most gets to define which record is real. On Ravencoin, that control is concentrated. "2Miners and RavenMiner currently control a majority of the network hash rate and have announced that they are mining a chain which excludes the exploited branch from height 4,487,776 onward," the notice states.
If enough miners follow them, the replacement chain becomes the legitimate one. "If that chain becomes the dominant chain, this may result in a deep chain reorganization of approximately three days," the post reads.
The developer who published the notice tried to limit the damage and was turned down. "I asked the pools to consider a more recent recovery point to reduce the impact on users, services and exchanges. That request was declined."




